Forum Discussion
Microsoft Foundry External MCP Server Traffic Routing via Corporate Firewall
You’re confirming whether a Standard Foundry Agent with network injection can route an external MCP tool call through Azure Firewall, because the call succeeds but no firewall event appears. Microsoft’s networking model says tool-server calls use a single-tenant data proxy in the delegated agent subnet; with bring-your-own VNet injection, a firewall can control egress to approved internet endpoints. Custom MCP servers, including private ones, are supported. Confirm the Foundry account was created with network injection, because adding it later is unsupported. Verify the route table is associated with the Microsoft.App/environments delegated subnet and its 0.0.0.0/0 route points to the firewall private IP. Invoke one tool at a UTC timestamp, then query AZFWApplicationRule and AZFWNetworkRule and confirm diagnostic settings are enabled. Avoid TLS inspection for required Foundry endpoints. If logs remain empty, open Microsoft support with the project ID, subnet, route table, firewall policy, MCP FQDN, and timestamp.